CVE-2011-1006
22.03.2011, 17:55
Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue crosses privilege boundaries.Enginsight
| Vendor | Product | Version |
|---|---|---|
| balbir_singh | libcgroup | 𝑥 ≤ 0.37 |
| balbir_singh | libcgroup | 0.1b:b |
| balbir_singh | libcgroup | 0.1c:c |
| balbir_singh | libcgroup | 0.2 |
| balbir_singh | libcgroup | 0.3 |
| balbir_singh | libcgroup | 0.31 |
| balbir_singh | libcgroup | 0.32 |
| balbir_singh | libcgroup | 0.32.1 |
| balbir_singh | libcgroup | 0.32.2 |
| balbir_singh | libcgroup | 0.33 |
| balbir_singh | libcgroup | 0.34 |
| balbir_singh | libcgroup | 0.35 |
| balbir_singh | libcgroup | 0.35.1 |
| balbir_singh | libcgroup | 0.36 |
| balbir_singh | libcgroup | 0.36.1 |
| balbir_singh | libcgroup | 0.36.2 |
| balbir_singh | libcgroup | 0.37:rc1 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libcgroup |
|
Common Weakness Enumeration
References